Privacy Policy
Last updated: 13 August 2026
This document describes what data VilyQ processes, where it is stored and who else has access to it. It is written to be verifiable rather than reassuring.
Who processes the data
VilyQ is a platform used by a distribution company (the “customer”) to manage its field sales team. For the data the customer enters — its locations, employees and sales — the customer is the data controller and VilyQ is a processor acting only on its instructions. For the customer's own account data (name, email, billing) VilyQ is the controller.
What data is processed
Account: name, email, role, language. Locations: customer name and company, address, coordinates, phone, company ID, VAT number, responsible person. Field work: visits with date and time, GPS coordinates and a photo (only if the company enabled GPS validation), sales with items and quantities, orders, invoices, stock movements. Technical: IP address and browser data in hosting logs, error reports.
Where it is stored
The database runs in AWS Frankfurt, Germany (eu-central-1). The application's server code runs on Vercel Frankfurt (fra1). Both are within the European Union. Files (visit photos, documents) are kept in the same infrastructure.
Separation between customers
Separation is not performed by application code but by the database itself. Each of the 42 tables has row level security enabled, with 122 rules in total binding access to the user's company. Even if the application had a bug, a query for another company's data is refused by the database. Within a company access narrows further: a sales rep sees their own locations, a regional manager their region.
What KriQ receives
KriQ is the analysis feature in the product and runs through Anthropic (USA). It receives only already-computed aggregate figures for that specific company: location and employee names, revenue for a period, visit counts, days since the last visit, trends. It does not receive raw database rows, does not receive another company's data, and database permissions remain its ceiling — it sees exactly what the person asking sees. Actions that change data are never executed automatically: KriQ proposes, a person confirms.
Security
Traffic is encrypted (TLS) and data is encrypted at rest. Passwords are not stored by VilyQ — they are handled by Supabase Auth and kept only as an irreversible hash. Sensitive actions are written to an audit log recording who, what and when: issuing an invoice, approving and rejecting an order, changing roles. Permissions are managed through per-module roles rather than job titles.
Access by VilyQ
VilyQ staff have technical access to the infrastructure for support and troubleshooting. That access is used only for a specific reason. VilyQ does not sell data and does not provide it to third parties for marketing purposes.
Retention
Data is kept while the contract is active. After termination it is retained for up to 60 days so that recovery is possible in case of error or dispute, and then deleted. The customer may request earlier deletion in writing. Documents with tax significance (invoices) are kept for the statutory period regardless of termination.
Data subject rights
Every individual has the right of access, rectification, erasure, restriction of processing and data portability, as well as the right to object. Where VilyQ acts as a processor, requests are addressed to the company using the platform and VilyQ assists. For data where VilyQ is the controller, write to the address below.
Changes
If this policy changes materially, we notify customers by email before the change takes effect.
Sub-processors
These providers process data on VilyQ's behalf. The list is updated when it changes.
| Supabase | Database, authentication, files | EU — Frankfurt |
| Vercel | Application hosting | EU — Frankfurt |
| Anthropic | KriQ — analysis over aggregate figures | USA |
| Stripe | Subscription payments | EU / USA |
Contact
Questions about this policy and data access requests: demo@vilyq.com